Back to skill

Security audit

DrugFlow

Security checks for vulnerabilities and agentic risk

Overview

This DrugFlow skill appears purpose-aligned, but it deserves review because it handles credentials and can upload data and create token-consuming remote jobs with weak safeguards.

Install only if you trust the DrugFlow endpoint and need these automations. Prefer HTTPS, avoid passing real passwords on the command line, protect and delete cookie jars, use test accounts and non-sensitive datasets first, and require explicit user approval before signup, workspace creation, uploads, or job submission that may consume tokens.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/common/drugflow_api.py:9
Finding

Credentials and session cookies may be exposed through insecure transport, command-line arguments, and predictable temporary files

Content
View full analysis
str: value = (base_url or "").strip() if not value: raise ValueError("base_url cannot be empty") if not value.startswith(("http://", "https://")): value = f"https://{value}" return value.rstrip("/") ``` The password is subsequently submitted to the selected endpoint: ```python def signin(self, email: str, password: str, phone: Optional[str] = None) -> Dict[str, Any]: payload_data: Dict[str, str] = { "email": email, "password": password, # Some deployments keep LoginUserForm.phone as required even for email login. "phone": phone or "0", } payload = self.request_or_raise( "POST", "/signin", data=payload_data, ) if payload.get("detail") != "ok": raise RuntimeError(f"signin did not return detail=ok: {payload}") return payload ``` All remote-flow scripts require the password as a command-line argument. For example: ```python parser.add_argument("--base-url", required=True, help="Example: http://127.0.0.1:8888") parser.add_argument("--email", required=True) parser.add_argument(" ...[truncated 3413 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/common/test_common_apis.py:20
Finding

Optional signup smoke test creates accounts with a publicly known default password

Content
View full analysis
str: _, sep, domain = signin_email.partition("@") picked_domain = domain if sep else "example.com" suffix = int(time.time()) return f"codex-skill-{suffix}@{picked_domain}" ``` The default password is then used in the signup request: ```python signup_payload = signup_client.signup( email=signup_email, password=args.signup_password, name=args.signup_name, organization=args.signup_organization, allow_exists=True, ) ``` ### Technical Analysis When `--test-signup` is enabled without an explicit `--signup-password`, the script registers a user with the static password `CodexSkill_12345`. This value is present in the distributed Skill and must therefore be treated as public. The generated email format is also predictable because it combines the prefix `codex-skill-`, the current Unix timestamp, and the domain taken from the sign-in email. Predictability is not independently an authentication vulnerability, but it lowers the effort required to identify accounts likely to use the known password. The documentation notes that some deployments may create inactive users pending activation. That behavior reduces immediate e ...[truncated 1551 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Yes, this is a mismatch. The description claims a substantial multi-flow API workflow skill with executable procedures across many DrugFlow operations. However, the actual code chunk is only an __init__.py file containing a brief docstring: it neither defines helpers nor performs any API calls or workflow steps. The code’s primary purpose, as shown, is merely to label a shared helpers package, which is materially different from the declared functional scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description emphasizes an API workflow skill for executing repository workflows like login, workspace retrieval, job listing, screening, docking-related jobs, and other end-to-end platform actions. However, the supplied code does not implement API calls, workflow orchestration, authentication, job handling, or Django/repository integration. Its actual purpose is a standalone structural-biology helper: parsing PDB HETATM records, filtering ligands, choosing the largest ligand or a selected site, and computing docking pocket parameters from coordinates. While pocket computation could be tangentially related to docking, this chunk is not an executable multi-flow API workflow skill as declared; it is a separate local parsing/geometry utility. Therefore the description materially misrepresents the code’s primary behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code only implements a narrow subset of the declared functionality: signup/signin, workspace retrieval/ensuring, balance retrieval, and job listing. It does not contain any logic for the additional end-to-end scientific workflows named in the description, such as virtual screening, docking, ADMET, rescoring, structure extraction, or molecular factory operations. While the implemented behavior is consistent with part of the description, the declared purpose materially overstates the skill's capabilities, so this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill clearly instructs the agent to read local reference files and run API-oriented scripts, which implies file-read and network-capable behavior, yet it declares no explicit tool scope such as allowed tools or permissions. That omission weakens least-privilege controls and makes accidental or overbroad execution more likely, especially for a skill that can authenticate, create jobs, and interact with remote services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages login, registration, API calls, job creation, and script execution but does not clearly warn that these steps may perform network activity, consume credits/tokens, create persistent remote jobs, or affect user accounts and data. In an agent setting, that omission can lead to non-consensual side effects or unintended transactions because the user may not realize the skill is operational rather than merely informational.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The flow document instructs users to submit raw credentials and persist an authenticated session cookie in a predictable local file without any warning about credential handling, cookie protection, or cleanup. In an agent-skill context, this increases the chance that secrets or reusable session material are exposed via shell history, logs, shared temp directories, or multi-user systems.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/flows/docking/call-flow.md (reported line 8)May include surrounding context.

  1. This repo defaults to session auth for REST APIs.
  2. Sign in:
bash
curl -sS -c /tmp/drugflow.cookies -b /tmp/drugflow.cookies \
  -X POST "http://127.0.0.1:8888/signin" \
  -d "email=YOUR_EMAIL" \
  -d "password=YOUR_PASSWORD"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation shows example commands passing a password directly on the command line (--password secret). Command-line secrets are commonly exposed through shell history, process listings, CI logs, and shared terminal transcripts, which can lead to credential disclosure. In a workflow skill intended for agents and automation, users may copy these examples verbatim, increasing the likelihood of unsafe secret handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The flow includes concrete login and session-cookie examples using real external endpoints, but provides no warning about handling credentials, cookie files, or the sensitivity of workspace and balance data. In an agent-executable skill, this increases the chance that users or agents will place secrets on disk (/tmp) or transmit production credentials without understanding privacy implications.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This example instructs posting email and password to an external service and storing authenticated session cookies in a predictable local file under /tmp. While normal for API documentation, in an agent skill this is security-relevant because automated execution could expose credentials through process arguments, shell history, logs, or other local users reading the cookie jar.

Content

Scanner excerpt · references/flows/molecular-factory/call-flow.md (reported line 7)May include surrounding context.

  1. Base URL example: https://new.drugflow.com
  2. Session auth by /signin:
bash
curl -sS -c /tmp/drugflow.cookies -b /tmp/drugflow.cookies \
  -X POST "https://new.drugflow.com/signin" \
  -d "email=YOUR_EMAIL" \
  -d "password=YOUR_PASSWORD"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The flow instructs users to submit credentials and persist authenticated session cookies to a local file without warning that sensitive authentication material will be stored on disk. In an agent-skill context, this is dangerous because automation may handle real user secrets non-interactively, increasing the chance of credential exposure through logs, shared temp directories, or later reuse by other processes.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/flows/admet/call-flow.md (reported line 8)May include surrounding context.

  1. REST API uses session auth (/signin) by default.
  2. Sign in:
bash
curl -sS -c /tmp/drugflow.cookies -b /tmp/drugflow.cookies \
  -X POST "https://new.drugflow.com/signin" \
  -d "email=YOUR_EMAIL" \
  -d "password=YOUR_PASSWORD"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/flows/rescoring/call-flow.md (reported line 8)May include surrounding context.

  1. REST API uses session auth (/signin) by default.
  2. Sign in:
bash
curl -sS -c /tmp/drugflow.cookies -b /tmp/drugflow.cookies \
  -X POST "https://new.drugflow.com/signin" \
  -d "email=YOUR_EMAIL" \
  -d "password=YOUR_PASSWORD"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The examples direct users to upload local protein and ligand files to a remote service but do not clearly disclose that local data leaves the system. In this repository's executable workflow context, that omission can cause accidental exfiltration of proprietary, regulated, or otherwise sensitive scientific data when the skill is run by an agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The flow documents logging in with raw email/password and storing an authenticated session cookie in a predictable file under /tmp without warning about credential handling, cookie theft, or cleanup. In a shared workstation, CI runner, or multi-user agent environment, another local process or user could read the cookie jar and hijack the session, especially because the skill is explicitly designed for executable end-to-end workflows.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/flows/structure-extract/call-flow.md (reported line 11)May include surrounding context.

  1. REST API uses session auth (/signin) by default.
  2. Sign in:
bash
curl -sS -c /tmp/drugflow.cookies -b /tmp/drugflow.cookies \
  -X POST "https://new.drugflow.com/signin" \
  -d "email=YOUR_EMAIL" \
  -d "password=YOUR_PASSWORD"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The flow instructs users to submit credentials and persist an authenticated session cookie to a local file, but it provides no warning about handling secrets or protecting the cookie jar. In an agent/automation context, this increases the chance that credentials or reusable session tokens are exposed through logs, shared temp paths, or subsequent tool access, enabling account compromise.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This command transmits user email and password to an external service and establishes a persisted authenticated session, which is sensitive behavior for an agent skill. Even though the endpoint appears legitimate and uses HTTPS in the example, the skill normalizes direct credential submission and cookie reuse without safeguards, making accidental exfiltration or misuse more likely.

Content

Scanner excerpt · references/flows/virtual-screening/call-flow.md (reported line 15)May include surrounding context.

1) Register or Sign In

  1. Sign in (recommended for automation):
bash
curl -sS -c "$COOKIE_JAR" -b "$COOKIE_JAR" \
  -X POST "$BASE_URL/signin" \
  -d "email=YOUR_EMAIL" \
  -d "password=YOUR_PASSWORD"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation shows a command line example with a literal email and password argument, which normalizes passing secrets directly on the command line. In practice, command-line secrets may be exposed through shell history, process listings, logs, or screenshots, creating a real credential-handling risk even in example documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script accepts email and password as inputs and sends them during client.signin(args.email, args.password), but the file provides no confirmation prompt, warning print, or explanatory comment/docstring disclosing that credentials will be transmitted to the remote service. For code files, outbound transmission of sensitive data should have some visible disclosure unless already clearly documented in the skill description, which is not present in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The job creation request sends dataset identifiers or direct SMILES input to /api/jobs, which is a network operation that transmits potentially sensitive user scientific data. Aside from the script name and argument structure, there is no explicit disclosure, prompt, or comment warning users that supplied molecular inputs will be sent to the configured remote server.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code transmits sensitive user credentials, including email and password, to a remote /signin endpoint, but there is no confirmation prompt, logging/print disclosure, or explanatory docstring/comment warning the user that authentication data will be sent over the network. Under the code-file criteria, network calls that transmit user or system data should be flagged when they lack any form of user disclosure and the warning is not otherwise visible in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The signup method submits email, name, organization, and password fields to /signup, which affects user data and transmits sensitive information over the network. The file contains no confirmation prompt, user-facing disclosure, or descriptive docstring/comment explaining that account registration data will be sent externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script accepts a password via command-line arguments and then uses those credentials to perform sign-in and signup HTTP operations, but it provides no warning in help text, comments, or output that credentials will be transmitted to a remote service. For a code file, network calls involving user credentials should have some visible disclosure unless the warning is documented elsewhere in markdown, which is not present in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sends fixed Chinese strings such as "数据中心" in the generated job arguments, which imposes a specific language/locale in the skill's behavior. There is no user opt-in, locale selection, or comment indicating that this is required for a region-specific API, so it appears to violate the language/locale policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.